Encrypted on your Mac with age before it goes anywhere. One list of who can read it. Free for five people.
Remove a person and every value they had access to is re-encrypted on your Mac, before the change is accepted. There is no window where they can still read new values, and no background job that gets round to it later.
What it does not do, and what no tool can do, is reach backwards. Anything they already pulled, they still have. Rotate that at the source: the database, the provider. Not just here.
Read the full model, including the narrow race we have not closed yet.
We didn't invent our own cryptography. MiniEnv uses age, the same standard the serious tools rely on. Values are encrypted on your machine before they leave it, so our server only ever stores ciphertext. If the whole database leaked tomorrow, an attacker would walk away with unreadable blobs.
Read the full security page: how push-to-Vercel works when we cannot read your values, everything our server can still see if it is breached tomorrow, and the six limitations we have not fixed yet.
A service-account JSON, an Apple .p8, a PEM or SSH deploy key, recovery codes, a connection string, a plain note. Same encryption as your env vars, kept as a separate collection so nothing that touches .env files or Vercel can reach it.
Each entry gets a free-text label, not a shouty variable name, and a kind that only picks an icon. No client is allowed to parse a value because of it.
Vault, Doppler and Infisical are built for security teams: roles, policies, compliance dashboards. If three people share a Stripe key, none of that helps.
Prices from each vendor's public pricing page, checked 27 August 2026. Infisical bills "any human or machine that authenticates" as an identity, so CI tokens count as seats.
The CLI does the same encryption on your machine, with the same Keychain identity as the app. No command ever prints a value, at any verbosity.
One download either way. Pro is unlocked inside the app, whenever you actually need it.